Privacy
ai-bom stores the minimum needed to operate: scan results (repository name, detected configuration and dependency findings), and — if you sign in — your email. GitHub tokens you provide for org scans are stored encrypted and used only to read the repositories you granted; revoke them on GitHub at any time. We never store repository file contents, only the findings extracted from them.
Report links are unlisted: anyone with the URL can view that report. Reports for private repositories are only created through your signed-in org scans. We don't sell data and we don't train models on your repositories. We use Stripe for billing.
Questions: hello@basenull.com.